Ransomware
Conduent Business Services SafePay Ransomware Attack
Primary Source βIncident Details
Conduent, a company providing payment processing and document services to major health insurers and state government programs, was breached by the SafePay ransomware group. Attackers had access from October 21, 2024 to January 13, 2025, exfiltrating over 8 terabytes of data. At least 25 million Americans were affected; ~15.5 million in Texas alone. Stolen data included names, SSNs, medical and health insurance information. SafePay threatened to publish data if ransom was not paid; Conduent is no longer listed on the leak site (ransom likely paid or data sold). Texas AG investigation opened. At least 10 federal class action lawsuits filed by February 2026. Considered by some sources as potentially the largest breach in US history by record count.
Technical Details
- Initial Attack Vector
- Unknown initial access; attackers had persistent access from October 21, 2024 to January 13, 2025
- Malware Family
- SafePay ransomware
Timeline
- 2024-10-21 Breach occurred
- 2025-02-01 Publicly disclosed
- 2025-06-01 Customers notified